Trojan

Trojan.Win32.Copak.mtlm removal tips

Malware Removal

The Trojan.Win32.Copak.mtlm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mtlm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.mtlm?


File Info:

name: 1125FD551F44620072C6.mlw
path: /opt/CAPEv2/storage/binaries/5aeb5d5f3cdb65e415dbb3224da96006d3b4fc621155a649739bf8d5dfe7aa03
crc32: 33170728
md5: 1125fd551f44620072c6a5c3977f8a30
sha1: fac81a7bf04d1077f3b9152fc60fed70f6fb3cd3
sha256: 5aeb5d5f3cdb65e415dbb3224da96006d3b4fc621155a649739bf8d5dfe7aa03
sha512: ec5e997e693dd972a6c4ac2e535ec147f0fd951c7d1f05653fcdd8f99ebbc85f7b6ac3bcbffffb5a9a2623a34f82000b4c89da41ee268d448a3227468440c0cf
ssdeep: 12288:2+Wd3wcPx1nMHJ7pTFqsHeFWdioc5z42QmAz8481eJGAqqFqsHeFWdI:2+Wd3BXib+FKiNzV+z844BAqqb+FKI
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C205020CFEC242B3C44AECB3E5E675599AAA838B1346384BEDB6CD5791C223C415DF25
sha3_384: f2859b5eec1d1dad2b590964e4a8090ffe185c34cf9671b9e2e7ba5d0c053e4a9832db4f7908381b38b0d64ccd121e03
ep_bytes: 68e99010275ab8e08d3f2468d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mtlm also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Malware.Razy-9935070-0
FireEyeGeneric.mg.1125fd551f446200
McAfeeGenericRXAA-FA!1125FD551F44
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1315417
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.51f446
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.mtlm
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.870640
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfb9a8
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.870640
JiangminTrojan.Copak.brwy
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Injector
ArcabitTrojan.Razy.DD48F0
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34160.YuZ@aOhSZ5
ALYacGen:Variant.Razy.870640
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazrlSQ2xMsuJOx5NpRhiU0Xu)
YandexTrojan.Copak!N+Q1m/awrhU
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.mtlm?

Trojan.Win32.Copak.mtlm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment